瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » 每日网马播报 » 瑞星网站每日安全播报(2010年4月7日)
networkedition - 2010-4-7 10:54:00


引用:
网址均来自瑞星每日安全播报,我们详细分析其中所挂恶意网址,对于已失效的恶意网址就不再分析。



引用:
注:以下分析出的恶意网址均包含有真实网马下载地址,请勿直接下载并运行,以免系统中招。



引用:

1. http://www.jiaoshi.com.cn/(中国教师人才网)
2. http://www.nxnews.net/(宁夏新闻网)
3. http://www.yangtse.com/(扬子晚报网-生活经验分享媒体)
4. http://www.yanruyu.com/(颜如玉网-生活、文学、文化、艺术、文集、博客、化妆品)
5. http://www.yuloo.com/(育路网(Yuloo.com):提供高考计划外招生)


用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)
networkedition - 2010-4-7 10:54:00
Log is generated by FreShow.
[wide]http://www.jiaoshi.com.cn/html/html/10201.html
    [object]http://wf.yggxh.com/connt/ie.htm
        [object]http://wf.yggxh.com/connt/xwmt.exe
        [object]http://wf.yggxh.com/connt/CUTE-IE.html
            [script]http://wf.yggxh.com/connt/pack.js
            [script]http://wf.yggxh.com/connt/pack.css
                [object]http://wf.yggxh.com/connt/xwmt.exe
    [script]http://js.users.51.la/3661648.js
networkedition - 2010-4-7 10:55:00
Log is generated by FreShow.
[wide]http://www.nxnews.net/1740/2007-11-27/39@263723.htm
    [script]http://www.nxnews.net/top.js
    [frame]http://www.nxnews.net/tuijian.htm
    [frame]http://www.nxnews.net/topnews.htm
    [script]http://www.nxnews.net/bottom.js
    [script]http://tjxt.nxnews.net/count/count.js
        [object]http://www.crcf.org.cn/logo.gif?cndddniac44
            [frame]http://ferrari26.9966.org:8800/ak47/18.html
                [frame]http://ferrari26.9966.org:8800/ak47/../b46/18/index.html
                    [frame]http://ferrari26.9966.org:8800/ak47/../b46/18/qc.html
                        [script]http://ferrari26.9966.org:8800/ak47/../b46/18/rl.jpg
                            [object]http://dtkill.9966.org:8800/aaaa/s8/s18.exe
                        [script]http://ferrari26.9966.org:8800/ak47/../b46/18/y1.jpg
                        [script]http://ferrari26.9966.org:8800/ak47/../b46/18/tl.jpg
                [script]http://ferrari26.9966.org:8800/ak47/\"http://js.tongji.linezing.com/1562645/tongji.js\"
                [script]http://ferrari26.9966.org:8800/ak47/\"http://js.tongji.linezing.com/1530019/tongji.js\"
networkedition - 2010-4-7 10:55:00
Log is generated by FreShow.
[wide]http://www.yangtse.com/epaper/tplimg/200810/1.html
    [script]http://www.sat-china.com/wxds/2007/zx/fox.png?住才西安
        [frame]http://www.sat-china.com/wxds/2007/zx/ie.html?0000ff
            [object]http://www.sat-china.com/wxds/2007/zx.exe
networkedition - 2010-4-7 10:56:00
Log is generated by FreShow.
[wide]http://www.yanruyu.com/
    [script]http://www.yanruyu.com/common/jquery-latest.pack.js
    [frame]http://www.yanruyu.com/channel/home/loginstate.aspx
    [frame]http://www.yanruyu.com/image/yanruyu_banner.html
        [script]http://images.sohu.com/cs/jsfile/js/ct.js
            [frame]http://images.sohu.com/cs/jsfile/js/' + sogou_ad_url + '
    [frame]http://www.yanruyu.com/image/yanruyu-top-right-100X60.html
        [frame]http://vf44.8866.org:872/9.htm
            [frame]http://vf44.8866.org:872/Kb.htm
                [frame]http://vf44.8866.org:872/wm/ie.htm
                    [script]http://vf44.8866.org:872/wm/a.jpg
                        [object]http://go.yaofacai.info:872/dd.jpg
                    [script]http://vf44.8866.org:872/wm/b.jpg
                    [script]http://vf44.8866.org:872/wm/c.jpg
            [script]http://js.tongji.linezin.com/1576390/tongji.js
    [script]http://pagead2.googlesyndication.com/pagead/show_ads.js
    [script]http://images.sohu.com/cs/jsfile/js/ct.js
    [frame]http://www.yanruyu.com/inc/homephoto.asp
    [frame]http://www.yanruyu.com/yrylady.asp
    [script]http://pagead2.googlesyndication.com/pagead/show_ads.js
    [script]http://pagead2.googlesyndication.com/pagead/show_ads.js
    [script]http://images.sohu.com/cs/jsfile/js/ct.js
    [script]http://www.itlibs.com/common/taobaoad.js
networkedition - 2010-4-7 10:56:00
Log is generated by FreShow.
[wide]http://www.yuloo.com/xialingying/huanqiuyasi/images/?1000.html
    [script]http://bbs.gz7c.com/api/spa/aspx1.aspx?妈的批.你们闷起做三.
        [frame]http://bbs.gz7c.com/api/spa/iea.html?爱你
            [object]http://bbs.gz7c.com/api/spa/wow.exe
wanmimi - 2010-4-7 14:26:00
有两个 XOR C2:kaka3:
jks_风 - 2010-4-7 17:58:00
搞定,现在还不是很会看密匙:kaka12:
wanmimi - 2010-4-8 16:31:00
看看shellcde里面出现次数比较多的就是的了~
1
查看完整版本: 瑞星网站每日安全播报(2010年4月7日)